Payment service security protection method and system based on block chain
By adopting a distributed node deployment and consensus mechanism based on blockchain in the payment system, the problems of vulnerability to attacks and insufficient data security in traditional payment systems are solved, and the security and stability of payment services and efficient data protection are achieved.
Patent Information
- Application Number
- CN202510445449.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-10
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2045-04-10
AI Technical Summary
Traditional payment systems rely on centralized servers and are prone to attack, tampering with or deleting transaction data, resulting in paralysis of payment services and privacy leakage.
The blockchain-based payment service security protection method is adopted, and by determining the deployment strategy of blockchain nodes, a distributed node is established, a consensus node that meets the current payment service, transaction security verification is carried out on the payment service, and payment data is encrypted and stored in pieces.
It realizes the safe and stable completion of payment services, prevents malicious attacks, ensures the security of payment data, and prevents data from being maliciously modified or deleted.
Smart Images

Figure CN119963191A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of secure payment technology, and in particular to a payment service security protection method and system based on blockchain. Background Art
[0002] With the acceleration of globalization, the scale of international trade continues to expand, and the demand for payment systems is growing. Traditional payment systems rely on centralized servers to store transaction data. When centralized servers are attacked, the entire payment business will be paralyzed, and transaction data can be easily tampered with or deleted, causing privacy leaks.
[0003] Blockchain technology is a decentralized distributed ledger technology that ensures the security and immutability of data through encryption algorithms. Each block contains a certain number of transaction records and is linked to the previous block through a hash function, forming an ever-extending chain structure.
[0004] How to apply blockchain to payment services to solve problems existing in traditional payments is a problem that needs to be solved in the payment business. Summary of the invention
[0005] The present invention provides a payment service security protection method and system based on blockchain, which are used to solve the problems raised in the background technology.
[0006] A payment service security protection method based on blockchain, comprising: S1: Determine the deployment strategy for blockchain nodes based on the overall payment business scope, and establish distributed nodes based on the deployment strategy; S2: Based on security rules, select a consensus node that meets the current payment business from the distributed nodes; S3: Perform transaction security verification on the current payment service based on the consensus node, and complete the current payment service after the verification is passed; S4: Encrypt and store the payment data generated by the current payment business in shards in the storage node.
[0007] Preferably, in S1, based on the overall payment business scope, a deployment strategy for blockchain nodes is determined, and distributed nodes are established based on the deployment strategy, including: Based on the overall payment business scope, construct an information matrix of payment business; Based on the information matrix and in combination with the deployment principles, determine the deployment strategy for the blockchain nodes; The node positions and node types are determined from the deployment strategy, and the distributed nodes are constructed based on the node positions and node types.
[0008] Preferably, in S2, based on security rules, a consensus node that meets the current payment service is selected from distributed nodes, including: Obtain the publicly available historical transaction information of each node in the distributed nodes; Based on historical transaction information, distributed nodes rate each other's business capabilities and obtain the capability score of each node; Based on security rules, each node in the distributed nodes is rated for trustworthiness to obtain a trust score for each node; Based on the current payment business, select a node to be selected from the distributed nodes that satisfies the regional location distribution; Based on the predicted transaction situation of the current payment business, determine the capability requirements and trust requirements for the node, and determine the capability weight and trust weight; Based on the capability score and capability weight, trust score and trust weight, determine the comprehensive score of the node to be selected, and select the node to be selected whose comprehensive score is greater than the preset score as the consensus node; Based on the consensus mechanism, the consensus capability of consensus nodes is established.
[0009] Preferably, in S3, transaction security verification of the current payment service is performed based on the consensus node, including: Analyze the current payment business based on the consensus node to obtain the payment operation; Verifying the payment operation based on the consensus node to obtain a first consensus result; Verifying the identity of the current payment service based on the consensus node to obtain a second consensus result; When both the first consensus result and the second consensus result indicate that the verification has been passed, it is determined that the transaction security verification has passed.
[0010] Preferably, in S3, completing the current payment service after verification is passed includes: Determine the target node for executing the payment service from the consensus node based on the current payment service; The current payment service is completed based on the target node.
[0011] Preferably, in S4, the payment data generated by completing the current payment service is encrypted and stored in the storage node in pieces, including: Slice the payment data to obtain multiple data slices; Based on the status of the storage node, each data slice is matched with a corresponding storage node to obtain the data allocation result; After the data slices are encrypted, the encrypted data are stored in corresponding storage nodes according to the data allocation result.
[0012] Preferably, the information matrix is used in combination with the deployment principle to determine the deployment strategy for the blockchain node, including: Acquire payment service scope information, traffic distribution information, fault frequency distribution information and attack frequency distribution information from the information matrix; Based on the payment business scope information, determine the node range and node location to be selected, and based on the traffic distribution information, determine the node distribution density in the node range to be selected; Determine a node selection result according to the node distribution density and the number of node distribution, obtain an initial distributed node based on the node selection result, and set a node type in the initial distributed node based on the node information in the initial distributed node; Determine the failure frequency of each node type based on the failure frequency distribution information, set a node type weight based on the failure frequency of each node type, determine the number of node types to be added based on the node type weight, and add nodes to the initial distributed node based on the number of added nodes to obtain a first adjusted distributed node; Determine a weighted value for node distribution density based on the attack frequency distribution information, determine a target node distribution based on the weighted value, and add nodes to the first adjusted distributed node based on the target node distribution to obtain a second adjusted distributed node; Based on the deployment principle, scoring the second adjusted distributed nodes to obtain a safe deployment scoring value and a stable deployment scoring value; When both the secure deployment score and the stable deployment score meet the preset score requirements, the second method for determining the adjusted distributed nodes is used as a deployment strategy for the blockchain node; Otherwise, when the security deployment score value does not meet the preset score requirements, the second adjusted distributed node is configured with shard storage rules to clarify the storage nodes of payment data; when the stable deployment score value does not meet the preset score requirements, the second adjusted distributed node is configured with load balancing rules to clarify the order in which the distributed nodes process payment services; the method for determining the configured second adjusted distributed node is used as the deployment strategy for the blockchain node.
[0013] Preferably, after encrypting the data slice, storing the encrypted data in the corresponding storage node according to the data allocation result includes: Encrypt the data slices respectively based on the encryption algorithm to obtain encrypted data slices, and obtain a first encryption key corresponding to the encryption algorithm; Based on the data allocation result, a corresponding relationship between the encrypted data slice and the storage node is established, and the corresponding relationship is encrypted to obtain a second encryption key; Dividing the first encryption key to obtain a preset number of initial key fragments with the same amount of data, processing the initial key fragments to obtain a plurality of target key fragments greater than a current preset number, and storing the plurality of target key fragments in different storage nodes respectively; The second encryption key is stored in the storage node. When the encrypted data piece is decrypted using the first encryption key, the storage node is triggered to retrieve the second encryption key, and the data piece is restored using the second encryption key to obtain the payment data. When the encrypted data piece cannot be decrypted using the first encryption key, the retrieval of the second encryption key is not triggered. Based on the data distribution result, the encrypted data piece is hash-signed and then stored in the corresponding storage node.
[0014] Preferably, the specific process of using the first encryption key to complete the decryption of the encrypted data slice is as follows: When receiving a payment data retrieval instruction, the retrieval instruction is first verified based on the hash signature. After the verification is passed, the target key fragment is obtained from the storage node. When the collected target key fragments are greater than or equal to the preset number, the acquisition of the target key fragment is completed; The obtained target key pieces are combined to obtain a first encryption key, the encrypted data piece is decrypted using the first encryption key, and the data piece is obtained according to the decryption result; When the storage node is triggered to retrieve the second encryption key, the data slices are integrated and restored using the second encryption key to obtain payment data.
[0015] A payment service security protection system based on blockchain, comprising: A node establishment module, used to determine the deployment strategy for blockchain nodes based on the overall payment business scope, and establish distributed nodes based on the deployment strategy; The node consensus module is used to select the consensus node that meets the current payment business from the distributed nodes based on security rules; The security verification module is used to perform transaction security verification on the current payment business based on the consensus node, and complete the current payment business after the verification is passed; The shard storage module is used to encrypt and store the payment data generated by the current payment business in shards to the storage node. Compared with the prior art, the present invention has achieved the following beneficial effects: By determining the deployment strategy for blockchain nodes based on the overall payment business scope, and establishing distributed nodes based on the deployment strategy, distributed nodes for payment business are established to ensure the safe and stable completion of payment business. Based on security rules, consensus nodes that meet the current payment business are selected from distributed nodes, and suitable nodes are selected for the current payment business to conduct transactions to ensure transaction security. Transaction security verification is performed on the current payment business based on the consensus node, and the current payment business is completed after the verification is passed. Transaction security verification is passed to prevent malicious attacks, and the payment data generated by the completion of the current payment business is encrypted and stored in the storage node in shards to ensure the security of the payment data. Through shard storage, the payment data can be effectively prevented from being maliciously modified or deleted.
[0016] Other features and advantages of the present invention will be described in the following description, and partly become apparent from the description, or understood by practicing the present invention. The purpose and other advantages of the present invention can be realized and obtained by the structures specifically pointed out in this application document.
[0017] The technical solution of the present invention is further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings: Figure 1 This is a flowchart of a payment service security protection method based on blockchain in an embodiment of the present invention; Figure 2 A flowchart of establishing a distributed node in an embodiment of the present invention; Figure 3 This is a structural diagram of a payment service security protection system based on blockchain in an embodiment of the present invention. DETAILED DESCRIPTION
[0019] The preferred embodiments of the present invention are described below in conjunction with the accompanying drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention, and are not used to limit the present invention.
[0020] Embodiment 1: The embodiment of the present invention provides a payment service security protection method based on blockchain, such as Figure 1 As shown, including: S1: Determine the deployment strategy for blockchain nodes based on the overall payment business scope, and establish distributed nodes based on the deployment strategy; S2: Based on security rules, select a consensus node that meets the current payment business from the distributed nodes; S3: Perform transaction security verification on the current payment service based on the consensus node, and complete the current payment service after the verification is passed; S4: Encrypt and store the payment data generated by the current payment business in shards in the storage node.
[0021] In this embodiment, the overall payment service scope includes a geographical area scope.
[0022] In this embodiment, the deployment strategy for the blockchain nodes is determined, for example, based on the aggregation of business traffic and the frequency of regional attacks.
[0023] In this embodiment, the security rule is, for example, the trust level of each node.
[0024] In this embodiment, transaction security verification includes verification of account balance, transaction amount, abnormal transaction behavior, etc.
[0025] In this embodiment, the payment data includes, for example, the transaction order amount, successful transaction orders, etc.
[0026] The beneficial effects of the above design scheme are: by determining the deployment strategy for blockchain nodes based on the overall payment business scope, and establishing distributed nodes based on the deployment strategy, the distributed nodes for payment business are established to ensure the safe and stable completion of the payment business; based on security rules, consensus nodes that meet the current payment business are selected from the distributed nodes, and suitable nodes are selected for the current payment business to conduct transactions to ensure transaction security; transaction security verification is performed on the current payment business based on the consensus node, and the current payment business is completed after the verification is passed; transaction security verification is performed to prevent malicious attacks; the payment data generated by the completion of the current payment business is encrypted and stored in the storage node in shards to ensure the security of the payment data; and sharded storage is used to effectively prevent the payment data from being maliciously modified or deleted.
[0027] Embodiment 2: Based on Example 1, the present invention provides a payment service security protection method based on blockchain, such as Figure 2 As shown, in S1, based on the overall payment business scope, a deployment strategy for blockchain nodes is determined, and distributed nodes are established based on the deployment strategy, including: Based on the overall payment business scope, construct an information matrix of payment business; Based on the information matrix and in combination with the deployment principles, determine the deployment strategy for the blockchain nodes; The node positions and node types are determined from the deployment strategy, and the distributed nodes are constructed based on the node positions and node types.
[0028] In this embodiment, the information matrix is used to represent the key information included in the overall payment business scope.
[0029] In this embodiment, the deployment principle is that security performance, stability performance, load balancing, etc. meet preset requirements.
[0030] In this embodiment, the node types include master nodes, verification nodes, storage nodes, etc.
[0031] The beneficial effects of the above design scheme are: by constructing an information matrix of payment services based on the overall payment business scope, a clear and effective information basis is provided for node deployment; based on the information matrix and in combination with the deployment principles, a deployment strategy for blockchain nodes is determined to ensure that the deployment strategy meets actual needs; the node location and node type are determined from the deployment strategy; distributed nodes are constructed based on the node location and node type to achieve the establishment of distributed nodes for payment services, thereby ensuring the safe and stable completion of payment services.
[0032] Embodiment 3: Based on Example 1, the embodiment of the present invention provides a payment service security protection method based on blockchain. In S2, based on security rules, a consensus node that meets the current payment service is selected from distributed nodes, including: Obtain the publicly available historical transaction information of each node in the distributed nodes; Based on historical transaction information, distributed nodes rate each other's business capabilities and obtain the capability score of each node; Based on security rules, each node in the distributed nodes is rated for trustworthiness to obtain a trust score for each node; Based on the current payment business, select a node to be selected from the distributed nodes that satisfies the regional location distribution; Based on the predicted transaction situation of the current payment business, determine the capability requirements and trust requirements for the node, and determine the capability weight and trust weight; Based on the capability score and capability weight, trust score and trust weight, determine the comprehensive score of the node to be selected, and select the node to be selected whose comprehensive score is greater than the preset score as the consensus node; Based on the consensus mechanism, the consensus capability of consensus nodes is established.
[0033] In this embodiment, the distributed nodes are allowed to rate each other to ensure fairness and openness of the ratings.
[0034] In this embodiment, the node address location distribution of the nodes to be selected meets the requirements of the current payment service.
[0035] The beneficial effects of the above design scheme are: by determining the comprehensive score value of the node to be selected based on the capability score and capability weight, trust score and trust weight, and selecting the node to be selected with a comprehensive score value greater than the preset score value as the consensus node, based on the consensus mechanism, the consensus capability of the consensus node is established, and consensus on distributed nodes is achieved, providing a basis for the smooth transaction of payment business at the consensus node, selecting suitable nodes for the current payment business to conduct transactions, and ensuring transaction security.
[0036] Embodiment 4: Based on Example 1, the embodiment of the present invention provides a payment service security protection method based on blockchain. In S3, transaction security verification of the current payment service is performed based on the consensus node, including: Analyze the current payment business based on the consensus node to obtain the payment operation; Verifying the payment operation based on the consensus node to obtain a first consensus result; Verifying the identity of the current payment service based on the consensus node to obtain a second consensus result; When both the first consensus result and the second consensus result indicate that the verification has been passed, it is determined that the transaction security verification has passed.
[0037] The beneficial effects of the above design scheme are: by parsing the current payment business based on the consensus node, the payment operation is obtained, the payment operation is verified based on the consensus node to obtain a first consensus result, the identity of the current payment business is verified based on the consensus node to obtain a second consensus result, when the first consensus result and the second consensus result both indicate that the verification has been passed, it is determined that the transaction security verification has passed, and the verification of the current payment business is realized from two aspects of identity and operation. Through transaction security verification, malicious attacks are prevented and transaction security is guaranteed.
[0038] Embodiment 5: Based on Example 4, the embodiment of the present invention provides a payment service security protection method based on blockchain. In S3, the current payment service is completed after the verification is passed, including: Determine the target node for executing the payment service from the consensus node based on the current payment service; The current payment service is completed based on the target node.
[0039] The beneficial effect of the above design scheme is: by determining the target node for executing the payment service from the consensus node based on the current payment service, the current payment service is completed based on the target node, and the current payment service is successfully completed in the distributed nodes.
[0040] Embodiment 6: Based on Example 1, the embodiment of the present invention provides a payment service security protection method based on blockchain. In S4, the payment data generated by the current payment service is encrypted and stored in the storage node in pieces, including: Slice the payment data to obtain multiple data slices; Based on the status of the storage node, each data slice is matched with a corresponding storage node to obtain the data allocation result; After the data slices are encrypted, the encrypted data are stored in corresponding storage nodes according to the data allocation result.
[0041] In this embodiment, the state of the storage node is, for example, a full load state.
[0042] The beneficial effects of the above design scheme are: by sharding the payment data to obtain multiple data slices, matching the corresponding storage nodes for each data slice based on the status of the storage nodes to obtain data allocation results, encrypting the data slices, and storing the encrypted data in the corresponding storage nodes according to the data allocation results to ensure the security of the payment data. Through sharded storage, the payment data can be effectively prevented from being maliciously modified or deleted.
[0043] Embodiment 7: Based on Example 2, the embodiment of the present invention provides a payment service security protection method based on blockchain, which determines the deployment strategy for blockchain nodes based on the information matrix and in combination with the deployment principle, including: Acquire payment service scope information, traffic distribution information, fault frequency distribution information and attack frequency distribution information from the information matrix; Based on the payment business scope information, determine the node range and node location to be selected, and based on the traffic distribution information, determine the node distribution density in the node range to be selected; Determine a node selection result according to the node distribution density and the number of node distribution, obtain an initial distributed node based on the node selection result, and set a node type in the initial distributed node based on the node information in the initial distributed node; Determine the failure frequency of each node type based on the failure frequency distribution information, set a node type weight based on the failure frequency of each node type, determine the number of node types to be added based on the node type weight, and add nodes to the initial distributed node based on the number of added nodes to obtain a first adjusted distributed node; Determine a weighted value for node distribution density based on the attack frequency distribution information, determine a target node distribution based on the weighted value, and add nodes to the first adjusted distributed node based on the target node distribution to obtain a second adjusted distributed node; Based on the deployment principle, scoring the second adjusted distributed nodes to obtain a safe deployment scoring value and a stable deployment scoring value; When both the secure deployment score and the stable deployment score meet the preset score requirements, the second method for determining the adjusted distributed nodes is used as a deployment strategy for the blockchain node; Otherwise, when the security deployment score value does not meet the preset score requirements, the second adjusted distributed node is configured with shard storage rules to clarify the storage nodes of payment data; when the stable deployment score value does not meet the preset score requirements, the second adjusted distributed node is configured with load balancing rules to clarify the order in which the distributed nodes process payment services; the method for determining the configured second adjusted distributed node is used as the deployment strategy for the blockchain node.
[0044] In this embodiment, the shard storage rules are configured such that data on Asian transactions is stored on nodes in China, Japan, and Singapore, and other nodes such as Europe are prevented from storing payment data.
[0045] In this embodiment, the load balancing rule enables the nodes to process the payment services more flexibly. Instead of waiting for a single node to process, the services are allocated to other identical nodes for processing, thereby improving processing efficiency.
[0046] In this embodiment, the information matrix also includes information on locations of deployable nodes involved in the business scope.
[0047] In this embodiment, the payment service scope information includes both parties of the payment service, the specific type of payment, etc.
[0048] In this embodiment, the traffic distribution information is the area involved in the payment business. For example, there are many payment businesses in Asia, and the traffic distribution in Asia is dense.
[0049] In this embodiment, the fault frequency distribution information is the frequency of faults occurring in each node during operation, which is related to the characteristics of the node itself.
[0050] In this embodiment, the attack frequency distribution information is the frequency at which the node is attacked by hackers during operation.
[0051] In this embodiment, the attack frequency distribution information ensures the security of node deployment, and the fault frequency distribution information ensures the stability of node deployment.
[0052] In this embodiment, the deployment principle determines the safety scoring criteria and the stability scoring criteria.
[0053] In this embodiment, the first adjustment distributed node adds a spare node for the failed node, so that when a failure occurs, the node can be transferred to the spare node in time.
[0054] In this embodiment, the second adjustment distributed node adds a spare node for the node where the attack occurs, so that when a failure occurs, it can be transferred to the spare node in time.
[0055] The beneficial effects of the above design scheme are: by selecting and deploying nodes based on payment business scope information, traffic distribution information, fault frequency distribution information and attack frequency distribution information, the practicality of node deployment is guaranteed, and based on the deployment principle, the second adjustment distributed node is scored to obtain a security deployment score value and a stable deployment score value; when the security deployment score value and the stable deployment score value both meet the preset scoring requirements, the determination method of the second adjustment distributed node is used as the deployment strategy for the blockchain node; otherwise, when the security deployment score value does not meet the preset scoring requirements, the second adjustment distributed node is configured with a shard storage rule to clarify the storage node of the payment data, and when the stable deployment score value does not meet the preset scoring requirements, the second adjustment distributed node is configured with a load balancing rule to clarify the processing order of the distributed node for processing payment business, and the determination method of the configured second adjustment distributed node is used as the deployment strategy for the blockchain node to ensure stability and security under the deployment strategy, and provide a basis for efficient and accurate completion of payment business.
[0056] Embodiment 8: Based on Example 6, the embodiment of the present invention provides a payment service security protection method based on blockchain, wherein after encrypting the data slice, the encrypted data is stored in the corresponding storage node according to the data allocation result, including: Encrypt the data slices respectively based on the encryption algorithm to obtain encrypted data slices, and obtain a first encryption key corresponding to the encryption algorithm; Based on the data allocation result, a corresponding relationship between the encrypted data slice and the storage node is established, and the corresponding relationship is encrypted to obtain a second encryption key; Dividing the first encryption key to obtain a preset number of initial key fragments with the same amount of data, processing the initial key fragments to obtain a plurality of target key fragments greater than a current preset number, and storing the plurality of target key fragments in different storage nodes respectively; The second encryption key is stored in the storage node. When the encrypted data piece is decrypted using the first encryption key, the storage node is triggered to retrieve the second encryption key, and the data piece is restored using the second encryption key to obtain the payment data. When the encrypted data piece cannot be decrypted using the first encryption key, the retrieval of the second encryption key is not triggered. Based on the data distribution result, the encrypted data piece is hash-signed and then stored in the corresponding storage node.
[0057] In this embodiment, the encryption algorithm is, for example, a symmetric encryption algorithm or an asymmetric encryption algorithm.
[0058] In this embodiment, the security of key storage is ensured by mechanically distributing the storage of the first encryption key.
[0059] In this embodiment, each data piece is encrypted to achieve payment data that cannot be restored even if part of the data is stolen.
[0060] In this embodiment, a correspondence between an encrypted data slice and a storage node is established, the correspondence is encrypted, and a second encryption key is obtained, thereby providing a basis for recovering the original payment data after obtaining the data slice, and triggering the acquisition of the second encryption key after obtaining the data slice to ensure storage security.
[0061] In this embodiment, the initial key fragment is processed to obtain multiple target key fragments greater than the current preset number, and the multiple target key fragments are respectively stored in different storage nodes, so that the data can be decrypted without obtaining all the target key fragments, thereby avoiding the inability to obtain payment data due to the failure of a single storage node.
[0062] The beneficial effects of the above design scheme are: by encrypting the data slices separately based on the encryption algorithm, the encrypted data slices are obtained, and the first encryption key corresponding to the encryption algorithm is obtained; by encrypting each data slice separately, the payment data that cannot be restored even if part of the data is stolen is realized; based on the data distribution result, a correspondence between the encrypted data slices and the storage nodes is established, and the corresponding relationship is encrypted to obtain the second encryption key; the first encryption key is divided to obtain a preset number of initial key slices with the same data volume, the initial key slices are processed to obtain multiple target key slices greater than the current preset number, and the multiple target key slices are stored in different storage nodes respectively. Now, it is not necessary to obtain all the target key slices to realize data decryption, so as to avoid the inability to obtain payment data due to the failure of a single storage node; based on the data distribution result, the encrypted data slices are hash signed and then stored in the corresponding storage nodes. Through shard storage, the payment data is effectively prevented from being maliciously modified or deleted.
[0063] Embodiment 9: Based on Example 8, the embodiment of the present invention provides a payment service security protection method based on blockchain. The specific process of using the first encryption key to complete the decryption of the encrypted data slice is as follows: When receiving a payment data retrieval instruction, the retrieval instruction is first verified based on the hash signature. After the verification is passed, the target key fragment is obtained from the storage node. When the collected target key fragments are greater than or equal to the preset number, the acquisition of the target key fragment is completed; The obtained target key pieces are combined to obtain a first encryption key, the encrypted data piece is decrypted using the first encryption key, and the data piece is obtained according to the decryption result; When the storage node is triggered to retrieve the second encryption key, the data slices are integrated and restored using the second encryption key to obtain payment data.
[0064] The beneficial effect of the above design scheme is: when an instruction to retrieve payment data is received, the retrieval instruction is first verified based on the hash signature. After the verification is passed, the target key slice is obtained from the storage node. When the collected target key slices are greater than or equal to the preset number, the acquisition of the target key slice is completed, the acquired target key slices are combined to obtain the first encryption key, the encrypted data slice is decrypted using the first encryption key, and the data slice is obtained according to the decryption result. When the storage node is triggered to retrieve the second encryption key, the data slice is integrated and restored using the second encryption key to obtain the payment data. Through sharded storage, the payment data can be effectively prevented from being maliciously modified or deleted, and the encryption security is achieved, and the recovery of the payment data is facilitated.
[0065] Embodiment 10: The present invention provides a payment service security protection system based on blockchain, such as Figure 3 As shown, including: A node establishment module, used to determine the deployment strategy for blockchain nodes based on the overall payment business scope, and establish distributed nodes based on the deployment strategy; The node consensus module is used to select the consensus node that meets the current payment business from the distributed nodes based on security rules; The security verification module is used to perform transaction security verification on the current payment business based on the consensus node, and complete the current payment business after the verification is passed; The shard storage module is used to encrypt and store the payment data generated by the current payment business in shards in the storage node.
[0066] In this embodiment, the overall payment service scope includes a geographical area scope.
[0067] In this embodiment, the deployment strategy for the blockchain nodes is determined, for example, based on the aggregation of business traffic and the frequency of regional attacks.
[0068] In this embodiment, the security rule is, for example, the trust level of each node.
[0069] In this embodiment, transaction security verification includes verification of account balance, transaction amount, abnormal transaction behavior, etc.
[0070] In this embodiment, the payment data includes, for example, the transaction order amount, successful transaction orders, etc.
[0071] The beneficial effects of the above design scheme are: by determining the deployment strategy for blockchain nodes based on the overall payment business scope, and establishing distributed nodes based on the deployment strategy, the distributed nodes for payment business are established to ensure the safe and stable completion of the payment business; based on security rules, consensus nodes that meet the current payment business are selected from the distributed nodes, and suitable nodes are selected for the current payment business to conduct transactions to ensure transaction security; transaction security verification is performed on the current payment business based on the consensus node, and the current payment business is completed after the verification is passed; transaction security verification is performed to prevent malicious attacks; the payment data generated by the completion of the current payment business is encrypted and stored in the storage node in shards to ensure the security of the payment data; and sharded storage is used to effectively prevent the payment data from being maliciously modified or deleted.
[0072] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention belong to the scope of this application document and its equivalent technology, the present invention is also intended to include these changes and variations.
Claims
1. A payment service security protection method based on blockchain, characterized in that: include: S1: Determine the deployment strategy for blockchain nodes based on the overall payment business scope, and establish distributed nodes based on the deployment strategy; S2: Based on security rules, select a consensus node that meets the current payment business from the distributed nodes; S3: Perform transaction security verification on the current payment service based on the consensus node, and complete the current payment service after the verification is passed; S4: Encrypt and store the payment data generated by the current payment business in shards in the storage node.
2. According to a blockchain-based payment service security protection method according to claim 1, it is characterized in that: In S1, based on the overall payment business scope, a deployment strategy for blockchain nodes is determined, and distributed nodes are established based on the deployment strategy, including: Based on the overall payment business scope, construct an information matrix of payment business; Based on the information matrix and in combination with the deployment principles, determine the deployment strategy for the blockchain nodes; The node positions and node types are determined from the deployment strategy, and the distributed nodes are constructed based on the node positions and node types.
3. According to a blockchain-based payment service security protection method according to claim 1, it is characterized in that: In S2, based on security rules, a consensus node that meets the current payment service is selected from distributed nodes, including: Obtain the publicly available historical transaction information of each node in the distributed nodes; Based on historical transaction information, distributed nodes rate each other's business capabilities and obtain the capability score of each node; Based on security rules, each node in the distributed nodes is rated for trustworthiness to obtain a trust score for each node; Based on the current payment business, select a node to be selected from the distributed nodes that satisfies the regional location distribution; Based on the predicted transaction situation of the current payment business, determine the capability requirements and trust requirements for the node, and determine the capability weight and trust weight; Based on the capability score and capability weight, trust score and trust weight, determine the comprehensive score of the node to be selected, and select the node to be selected whose comprehensive score is greater than the preset score as the consensus node; Based on the consensus mechanism, the consensus capability of consensus nodes is established.
4. According to a blockchain-based payment service security protection method according to claim 1, it is characterized in that: In S3, the transaction security verification of the current payment business is performed based on the consensus node, including: Analyze the current payment business based on the consensus node to obtain the payment operation; Verifying the payment operation based on the consensus node to obtain a first consensus result; Verifying the identity of the current payment service based on the consensus node to obtain a second consensus result; When both the first consensus result and the second consensus result indicate that the verification has been passed, it is determined that the transaction security verification has passed.
5. A payment service security protection method based on blockchain according to claim 4, characterized in that: In S3, after verification, the current payment service is completed, including: Determine the target node for executing the payment service from the consensus node based on the current payment service; The current payment service is completed based on the target node.
6. A payment service security protection method based on blockchain according to claim 1, characterized in that: In S4, the payment data generated by the current payment service is encrypted and stored in the storage node in pieces, including: Slice the payment data to obtain multiple data slices; Based on the status of the storage node, each data slice is matched with a corresponding storage node to obtain the data allocation result; After the data slices are encrypted, the encrypted data are stored in corresponding storage nodes according to the data allocation result.
7. A payment service security protection method based on blockchain according to claim 2, characterized in that: Based on the information matrix and in combination with the deployment principle, the deployment strategy for the blockchain node is determined, including: Acquire payment service scope information, traffic distribution information, fault frequency distribution information and attack frequency distribution information from the information matrix; Based on the payment business scope information, determine the node range and node location to be selected, and based on the traffic distribution information, determine the node distribution density in the node range to be selected; Determine a node selection result according to the node distribution density and the number of node distribution, obtain an initial distributed node based on the node selection result, and set a node type in the initial distributed node based on the node information in the initial distributed node; Determine the failure frequency of each node type based on the failure frequency distribution information, set a node type weight based on the failure frequency of each node type, determine the number of node types to be added based on the node type weight, and add nodes to the initial distributed node based on the number of added nodes to obtain a first adjusted distributed node; Determine a weighted value for node distribution density based on the attack frequency distribution information, determine a target node distribution based on the weighted value, and add nodes to the first adjusted distributed node based on the target node distribution to obtain a second adjusted distributed node; Based on the deployment principle, scoring the second adjusted distributed nodes to obtain a safe deployment scoring value and a stable deployment scoring value; When both the secure deployment score and the stable deployment score meet the preset score requirements, the second method for determining the adjusted distributed nodes is used as a deployment strategy for the blockchain node; Otherwise, when the security deployment score value does not meet the preset score requirements, the second adjusted distributed node is configured with shard storage rules to clarify the storage nodes of payment data; when the stable deployment score value does not meet the preset score requirements, the second adjusted distributed node is configured with load balancing rules to clarify the order in which the distributed nodes process payment services; the method for determining the configured second adjusted distributed node is used as the deployment strategy for the blockchain node.
8. A payment service security protection method based on blockchain according to claim 6, characterized in that: After the data slice is encrypted, storing the encrypted data in the corresponding storage node according to the data allocation result includes: Encrypt the data slices respectively based on the encryption algorithm to obtain encrypted data slices, and obtain a first encryption key corresponding to the encryption algorithm; Based on the data allocation result, a corresponding relationship between the encrypted data slice and the storage node is established, and the corresponding relationship is encrypted to obtain a second encryption key; Dividing the first encryption key to obtain a preset number of initial key fragments with the same amount of data, processing the initial key fragments to obtain a plurality of target key fragments greater than a current preset number, and storing the plurality of target key fragments in different storage nodes respectively; The second encryption key is stored in the storage node. When the encrypted data piece is decrypted using the first encryption key, the storage node is triggered to retrieve the second encryption key, and the data piece is restored using the second encryption key to obtain the payment data. When the encrypted data piece cannot be decrypted using the first encryption key, the retrieval of the second encryption key is not triggered. Based on the data distribution result, the encrypted data piece is hash-signed and then stored in the corresponding storage node.
9. A payment service security protection method based on blockchain according to claim 8, characterized in that: The specific process of decrypting the encrypted data slice using the first encryption key is as follows: When receiving a payment data retrieval instruction, the retrieval instruction is first verified based on the hash signature. After the verification is passed, the target key fragment is obtained from the storage node. When the collected target key fragments are greater than or equal to the preset number, the acquisition of the target key fragment is completed; The obtained target key pieces are combined to obtain a first encryption key, the encrypted data piece is decrypted using the first encryption key, and the data piece is obtained according to the decryption result; When the storage node is triggered to retrieve the second encryption key, the data slices are integrated and restored using the second encryption key to obtain payment data.
10. A payment service security protection system based on blockchain, specifically used in the payment service security protection method as claimed in claim 1, characterized in that: include: A node establishment module, used to determine the deployment strategy for blockchain nodes based on the overall payment business scope, and establish distributed nodes based on the deployment strategy; The node consensus module is used to select the consensus node that meets the current payment business from the distributed nodes based on security rules; The security verification module is used to perform transaction security verification on the current payment business based on the consensus node, and complete the current payment business after the verification is passed; The shard storage module is used to encrypt and store the payment data generated by the current payment business in shards in the storage node.
Citation Information
Patent Citations
Blockchain efficient management architecture based on cross-chain technology and working method thereof
CN112418860A
Block chain node verification method based on block chain payment and readable storage medium
CN112884467A
Decentralized encryption certification and authentication method with revocable bill
CN113205346A
Methods, devices, and systems for secure payments
US20210357915A1
Cited By
Payment order full-process intelligent processing method, device and equipment and storage medium
CN121010362A
A payment order whole-process intelligent processing method, device and equipment and storage medium
CN121010362B
Security protection method based on block chain and big data and block chain service system
CN121012616A